Correct src-dst single exclusion

Match the destination address in the output chain

Signed-off-by: Tom Eastep <teastep@shorewall.net>
This commit is contained in:
Tom Eastep 2024-03-08 11:50:49 -08:00
parent a9359d2610
commit 467cc4c252

View File

@ -1069,7 +1069,7 @@ sub add_common_rules ( $ ) {
if ( $setting & DBL_DST ) { if ( $setting & DBL_DST ) {
add_dbl_exclusion_ijump( $forward_option_chainref, $dbl_dst_target, $hostref, $dbl_ipset, 0, @state, @out_policy ); add_dbl_exclusion_ijump( $forward_option_chainref, $dbl_dst_target, $hostref, $dbl_ipset, 0, @state, @out_policy );
add_dbl_exclusion_ijump( $output_option_chainref, $dbl_dst_target, $hostref, $dbl_ipset, 1, @state, @out_policy ); add_dbl_exclusion_ijump( $output_option_chainref, $dbl_dst_target, $hostref, $dbl_ipset, 0, @state, @out_policy );
} }
$dbl_ipset = ''; # All ipset jumps have been added $dbl_ipset = ''; # All ipset jumps have been added